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1. Introduction 

An open question in air traffic management is whether or not algorithms can be realistically shown to meet 
Federal Aviation Administration (FAA) safety requirements. 

This current work shows such a demonstration is possible for a separation algorithm with perturbations 
from feedback control and atmospheric turbulence in a local setting. This project can accept a three to four 
magnitude increase in complexity and still remain viable, but clearly this is not enough of a margin to 
include every detail in a global analysis. Future work is needed in sensitivity analysis to determine what 
must be included in the simulation. 

Section two contains a probability and statistical analysis of a recent FAA requirement, and it is this analysis 
that most distinguishes this paper from other efforts. Section three presents the assumptions about the 
aircraft and flight space. Section four shows that the minimum-distance point determines the relative angle 
of approaching aircraft, and section five gives a pictorial description of the separation maneuver. Section six 
gives the precise description of the maneuver and a proof that it maintains separation if no perturbations are 
present. 

The aircraft proceed along their flight paths by means of feedback control, and section seven presents the 
control equations. The algorithm is simple and generic and needs more development. In its current state, it 
is intended to represent either control-with-pilot-in-the-loop or future-automatic-control. Once feedback 
control is introduced, it is possible to include perturbations in a realistic manner, and section eight describes 
its stochastic nature while section nine offers more commentary. The approach to perturbation in this paper 
is to examine distributions of increasing severity. If the algorithm can survive these distributions, then it 
can survive the real world perturbations. The severity of the examined perturbations can be seen in figure 
10 in section nine. 

This paper does not include a test of any decision algorithm since such a test should include the uncertainty 
due to instrumentation error where the position and heading of the aircraft are not precisely known. 

2. Representative FAA Requirement 
2.1 Probability 

The stated FAA goals are changing, but this paper addresses a recently expressed goal which was stated in 
terms of a moving average: no more than three incidents (of all types) over the last three years. Since there 
are about ten million flights per year, this translates into one or fewer incidents per 10 million (10 7 ) flights. 
The examination compares this moving average to a goal stated in terms of one year. There are two 
comments. First, future FAA goals or their interpretation may be different from the ones examined below, 
but the examination below outlines an approach to analyzing any stated goal. Second, as they stand, these 
goals are not probability statements, and they require interpretation. 

In the absence of information and for simplicity, the typical assumption is that all flights are equivalent and 
independent, and the typical interpretation of the goal is that the expected number of incidents for 10 



million flights be equal to one. Using the expectation does not require any more information from the FAA, 
but it does have a disadvantage as will be seen below. 

The disadvantage of this interpretation appears when we consider the probability of more than one incident 
during 10 million flights. It's reasonable to want the probability of more than one incident to be low, but it 
will be shown that using the expectation-interpretation does not guarantee this. On the other hand, the low- 
probability approach raises the question of how low the FAA wishes the probability to be. 

With the assumption that the flights are equivalent and independent, the distribution is binomial with the 
probability of an incident equal to 10- 7 per flight. The binomial distribution with parameter p gives the 
probability of zero or one incidents during 10 million flights as 


Q = (l-p)10000000 + 10000000 p (l-p)9999999 
= 0.7358 if p=le-7. 


(1) 


The probability of two or more incidents for p = le-7 is 1-Q = 0.2642. Hence, if the probability of an incident 
is equal to 10' 7 per flight, then the probability of more than one incident during 10 million flights is greater 
than 1/4. 


If the goal is a less than one in a hundred chance of more than one incident per ten million flights, then a 
little numerical work gives that for p = 1.5e-8, Q = 0.9898 and 1-Q = 0.0102. 

The moving average reduces the likelihood of not achieving the goal provided the probability of an incident 
during a flight is smaller than required. 

Suppose the probability of an incident is equal to 10- 7 per flight. Then 
Probjmore than one incident in a year | p=le-7} = 0.26. 

Probjmore than three incidents in three years | p=le-7) = 0.35. 

Whereas 

Probjmore than one incident in a year | p=le-8) = 0.0047. 

Probjmore than three incidents in three years | p=le-8} = 0.0003. 

The crossover point appears to be p=7e-8. 

Probjmore than one incident in a year | p=7e-8) = 0.16. 

Probjmore than three incidents in three years | p=7e-8) = 0.16. 

Returning to the interpretation of the FAA goal as a probability statement, one possibility is that the FAA 
would desire there is only 1 in N chance the goal not be met. A reasonable choice for N is some number 
between 10 and 100. Looking at the extremes, the computations below give values for p = probability of an 
incident during a flight if the requirement is a 1 in N chance the goal not be met. 

For N=10: 


The Probjmore than one incident in a year } = 0.10 requires p = 5.3e-8. 

The Probjmore than three incidents in three years) = 0.10 requires p = 5.8e-8. 


For N=100: 



The Probjmore than one incident in a year) = 0.01 requires p = 1.5e-8. 

The Probjmore than three incidents in three years) = 0.01 requires p = 2.7e-8. 

2.2 Probabilities and Confidence Levels for the Simulation 

A problem in establishing that a loss-of-separation-algorithm meets the FAA goal is that loss-of-separation 
is one incident among many. Hence, showing that the probability of loss-of-separation during a flight is less 
than le-7 may not be sufficient since there are other incidents and their probabilities accumulate. 

The problem is compounded since when studying incidents, especially the prevention of incidents, it is 
useful to distinguish between the potential for an incident and the incident itself. For instance, two aircraft 
on a collision course is a potential for an incident, but successful maneuvering will result in no incident. In 
addition, there may be multiple causes for an incident or an incident may require multiple causes. There 
may be no cause for alarm if two aircraft are on a collision course unless some malfunction prevents 
successful maneuvering. 

Hence, a precise probability analysis for loss-of-separation requires an encyclopedic knowledge of incidents 
and their causes which the author, at least, does not currently posses. Nevertheless, an elementary, 
incomplete analysis can offer some guidance. One approach in such an analysis is to be conservative: in the 
absence of complete information, use probabilities that overestimate the likelihood of dire events. 

We begin with a simplified scenario and then generalize it. Suppose there are K types of incidents. Let C i 
be the set of causes for incident i. Let B (for benign) be the set no causes for an incident. The initial 
simplifying assumption is that the C i and B partition the set of flight conditions. That is, the intersection of 
two different sets is empty, and their union is the entire set. This initial simplifying assumption is justified if 
incidents are rare and flights with more than one incident are rare enough to be ignored. 

With this approach, the study of an incident i consists of the study of the effect of the set C, . For instance, 
for this study of loss-of-separation, the causes are deviations from the flight paths due to feedback control 
and external perturbations. The realism of the simulation is increased by adding more causes. 

Let P(A i | C i ) be the conditional probability of an incident given that its causes appear. Then we want 

P(Ai | Ci)P(Ci) + P(A 2 | C 2 )P(C 2 ) + ...+ P(A k | C K )P(C K ) < p. (2) 

Based on the assumption that there is a positive probability that a flight is routine (no cause for an incident 
appears), we have 


P(Ci ) + ...+ P(C K ) < 1. 


( 3 ) 


Using this assumption, one way to accomplish this is to have P(Ai | Ci ) < p for all i since this gives 
P(Ai | C i ) P(C i ) + P(A 2 | C 2 )P(C 2 ) + ...+ P(A k | Ck)P(Ck) 

<pP(Ci) + pP(C 2 ) + ...+ pP(C K )<p[ P(Ci ) + ...+ P(C K ) ] <p. (4) 

The generalization of the above eliminates the partition requirement. That is, different C i can have a non- 
empty intersection, allowing for more than one incident per flight. The reasoning above still holds if P(Ci ) 
+ ...+ P(Ck) ^ 1, which this paper will assume. 

There are two cases where the approach above requires modification. First, if the sets C i have significant 
overlap, then the probabilities can sum to greater than 1. If a bound for the sum of probabilities is known 
and it is less than M, then it is sufficient to demonstrate P(A j | C i ) < q where q M < 1, although if there is 
significant overlap, then the studies will have to examine the probability that a single set of causes produces 
several incidents. 



Second, a scenario that would require a different type of analysis is if a set of causes had a high probability 
of producing an incident. That is, for some j, P(Aj | Cj ) cannot be made small. In this case, the alternative 
is to arrange things so that Cj is small. 

2.3 Confidence Levels for the Simulation 

The driver for Monte Carlo is the required confidence level which is a quantitative statement about the 
quality of the experiment. The frequency interpretation is that a confidence level of 100( 1 - h )% means 
there is a lOOh % or less chance that the experiment has misled us. This paper takes the point of view that 
the quality of the experiment should match the quality of the desired results. That is, if the probability to be 
established is p, then the confidence level should be at least 100( 1 - p )%. Hence, this paper will seek 
confidence levels of at least 100( 1 - le-7 )%. The confidence level may need to be even higher because loss- 
of-separation is only one incident among many. The final confidence level must combine the confidence 
level of a number of experiments. A result in combining confidence levels is the following. 

Theorem: Suppose (aj , b, ) is a 100( 1 - hj )% confidence interval for 0j for 1 < j < n, then [ (ai , bi ), ... (a n , 
b n )] isa 100(1 - hi -... - h n )% confidence interval for (0i ,..., 0 n ). 

For example, if there are 10 parameters to be estimated with a desired overall confidence level of 100( 1 - le- 
7 )%, then it is sufficient to estimate each of the parameters at the 100( 1 - le-8 )% level. In general, the 
individual confidence intervals do not need to be the same although the lack of confidence must have a sum 
less than or equal to le-7. Assuming all the trials are successful and given a desired probability p and 
confidence level h, the formula for computing the number of trials is 

(l-p) n =h (5) 

The reasoning is that ( 1-p ) is the probability of success (equivalently the non-occurrence of a failure) and 
repeated successes (n of them) implies that p is small. The probabilities (values of p) that appear in table 1 
are those computed in section 2.1. 


Requirement 

Value of 
p per 
flight 

Types of 
incidents is 100 

Confidence level 
is 

1 - p x (le-2) 
Number of trials 

Types of 
incidents is 
1000 

Confidence 
level is 
1- p x (le-3) 

Number of 
trials 

Expected number of incidents per 
year is 1 

1.0e-7 

2.1e+8 

2.3e+8 

Probability more than 1 incident a 
year is 0.10 

5.3e-8 

4.0e+8 

4.5e+8 

Probability more than 1 incident a 
year is 0.01 

1.5e-8 

1.5e+9 

1.7e+9 

Probability more than 3 incidents 
in 3 years is 0.10 

5.8e-8 

3.7e+8 

4.1e+8 

Probability more than 3 incidents 
in 3 years is 0.01 

2.7e-8 

8.2e+8 

9.0e+8 


Table 1. Number of trials given requirement and number of types of incidents 




2.4 Baseline for Simulation Effort 

Since the primary concern of this paper (and future efforts) is introducing realism while maintaining enough 
efficiency to establish the algorithms at the required probability and confidence levels, it is worthwhile to 
state what this study says about such efforts. 

The case chosen is that the requirement is the probability of more than 3 incidents in 3 years is 0.10 and there 
are 100 types of incidents. This requires 370,000,000 trials. Using a desktop computer, it took 25 hours to 
run this many trials. Assuming that it is feasible to rim the program for half a year, that it is feasible to use 
10 to 100 desktop computers, and that more efficient programs and faster computers are available, this 
implies it would be possible to run a simulation that is three or four orders of magnitude more complex. 

3. Assumptions 

As an early effort (for the author), there are a number of assumptions. (1) Only two aircraft at a time are 
considered. (2) All aircraft have the same speed and maintain this speed. (3) All scenarios are two- 
dimensional: all maneuvering is at a constant altitude. (4) The position and heading of all aircraft is 
precisely known. (5) Both aircraft know which one will make the collision-avoidance maneuver and what 
the maneuver will be. (6) Only approaching aircraft are considered for the reason below. 

This study restricts itself to approaching aircraft since for aircraft on nearly coincident courses, it is possible 
that a simple jog will not prevent loss-of -separation as illustrated in figure 1 



Fig. 1. Two aircraft on nearly coincident course 


The solution is either trivial: have one aircraft perform a circle for delay, or it is global: have one aircraft 
change altitude or arrange traffic to avoid such circumstances. Hence, the examination of nearly-coincident 
flight paths is postponed to a later study. 

4. The Minimum Point and Flight Angles 

For algebraic and geometric convenience, we establish the coordinate system such that the first aircraft 
travels along the x-axis and the two aircraft are their minimum distance apart when this first aircraft is at the 
origin. Initially, we let the second aircraft approach the first at any angle although we later restrict the study 
to aircraft with opposite headings. 

The first result is that the minimum-point for the second aircraft determines its flight angle except for the 
special case where the minimum point is (0,0). Let the minimum point for the second aircraft be (a,b). 


The graph is 




Fig. 2. The minimum points (0,0) and (a,b) for the two aircraft 


The parametric equations for the original paths for the first and second aircraft are 


X 1 =t 

y 1=0 

x 2 = a + tcosa 
y 2 = b + 1 sin a 


The distance-squared and its first and second derivative are 


s 2 = [a + tcosa - 1 ] 2 +[b + tsina]' 


= 2 [a + tcosa - 1 ][ cos - 1]+ 2[b + 1 sin a] [sin a] 


d s 


dt 
d 2 (s 2 
dt 2 


= 2 [cos a -l] 2 +2 [sin a]' 


( 6 ) 


( 7 ) 


Since the second derivative is positive, the zero-value of the first derivative gives a minimum. Skipping 
some algebraic steps, setting the first derivative equal to zero gives 

0 = a [cosct - 1] + bsinct ^ 

Placing sine and cosine on opposite sides of the equation, squaring, substituting, and solving the quadratic 
gives 


cos a = 


a 2 -b 2 
a 2 +b 2 


,1 


( 9 ) 


The value 1 corresponds to the two aircraft flying in parallel a constant distance apart. That case will not be 
considered in this study. 

Hence, except for the point (0,0), the minimum-distance point determines the flight path of the second 
aircraft with 



cos a = 



sin a = 


a 2 +b 2 
2 ab 


( 10 ) 


Since we are considering approaching aircraft, the cosine for the flight path of the second aircraft is negative. 
Hence, for the minimum-point (a,b), b > a. 

5. Description of Modified Flight Paths 

The trigonometric result in the last section makes it natural to divide the region containing the 
minimum=distance points into four sectors where the angles range from n/4 to n/2, from n/2 to 3n/4, from 
5n/4 to 3n/2, and from 3n/2 to 7n/4. 

The sine of the trajectory is positive in the first sector, negative in the second, positive in the third, and 
negative in the fourth. This change is illustrated in figure 3. 



Fig. 3. The changes in flight-path angle according to the location of the minimum-distance point 


The basic algorithm is that the second aircraft to reach the point of path-intersection turns into the path of 
the other aircraft. This algorithm does not cover parallel paths when the minimum-point lies on the y-axis, 
but for this study, this event has probability zero and is temporarily ignored since more robust algorithms 
must handle uncertainty due to instrumentation error. 

As an example, consider two aircraft whose initial minimum distance point is in the first sector which is 
displayed in figure 4. 




Fig. 4. Flight paths when the minimum-distance point lies in the first sector. 


The burden of maneuver falls on the aircraft moving along the x-axis. This is illustrated in figure 5. 



Fig. 5. The separation maneuver when the minimum-distance point lies in the first sector 


The maneuvers for sectors 2, 3, and 4 are given in figures 6, 7, and 8. 


► 



Fig. 6. The separation maneuver when the minimum-distance point lies in the second sector 


Fig. 7. The separation maneuver when the minimum-distance point lies in the third sector 



Fig. 8. The separation maneuver when the minimum-distance point lies in the fourth sector 


Because of the symmetrical nature of the separation maneuvers, it is sufficient to examine the case where the 
minimum-distance point lies in the first sector and the maneuver is given in figure 5. 

6. Analytical Demonstration of Separation 

We will scale the required minimum distance to 1. 

Showing the two paths maintain separation is an exercise in calculus. The idealized paths are either a single 
straight line or a sequence of straight lines. The demonstration pivots on the path that is a sequence of 
straight lines. Each segment is examined at its endpoints and zero value of the derivative of the distance 
when traversing the straight line segment. 

First, there are the endpoints and parametric equations for each of the segments. 

The first segment goes from (-4,0) to (-2,-2) along the path 


x i (t) = a - 4 cosa + t cos a 
y i (t) = b - 4 sina + t sina 

X 2(.)^4 t 

y2( t > = 0- ; y l 

for 0 < t < 2 -J2 


The second segment goes from (-2,-2) to (+2,-2) along the path 

x | (t) = a -(4-2V2) cosa + tcosa 
y i (t) = b - (4 - 2 V2 ) sina + t sina 
x 2 (t) = -2+t 

y 2 (t) = —2 

for 0 < t < 4 


The third segment goes from (+2,-2) to (+4,0) along the path 


Xj(t) = a + 2 V 2 cosa + tcosa 
y j(t) = b + 2 V 2 sina + tsina 


x 


y 


2 (0 - +2+ 

2 (t) = -2 + 



t 

t 


for 0 < t < 2 V2 


(ll) 


( 12 ) 


(13) 


We can first check the distances at the endpoints, which correspond to the corners for the path of the aircraft 
making the maneuver. 

The first endpoint and distance-squared from equations (11) are 

(- 4, 0) ; (a - 4 cosa, b - 4 sina) 
s 2 = [a - 4cosa + 4] 2 + [b - 4sinal 2 

L J L j ^ 

Since cosine is less than or equal to zero, the expression inside the first bracket is greater than or equal to 4, 
which implies the distance is greater than or equal to 4. 


The second endpoint and distance-squared from equations (12) are 



(- 2, - 2) ; (a - (4 - 2 a/2) cosa, b - (4 - 2 a/2) sina) 


s 2 = 


a - (4- 2 V2) cos a + 2 2 + b- (4-2^2) sina + 2 


( 15 ) 


Since cosine is negative, the term inside the first bracket is greater than or equal to 2, which implies the 
distance is greater than or equal to 2. 

The third endpoint and distance-squared from equations (13) are 


(-2, - 2); (a + 2 a/ 2 cos a, b + 2 a/ 2 sin a) for t = 0 
a + 2 a/ 2 cosa - 2 P + [b + 2 a/ 2 sin a + 2 P 


s 2 = 


(16) 


Since sine is positive, the term inside the second bracket is greater than or equal to 2, which implies the 
distance is greater than or equal to 2. 

The fourth endpoint and distance-squared from equations (13) are 


(+ 4, 0) ; (a + 4 a/ 2 cosa, b + 4 a/ 2 sina) 


s 2 = 


cl + 


4a/2 


cos a 


+ 


lb + 4 a/ 2 sinal 


(17) 


Since cosine is negative, the expression inside the first bracket is less than or equal to a-4, and since a is less 
than or equal to 1, the expression is less than or equal to -3, which implies the distance is greater than or 
equal to +3. 

Next we consider the distances while traversing the segments between the endpoints. 

The distance while traversing the first segment in terms of the parametric equations (11) is 


s 2 = 


a/2 


a-4 cosa + t cosa + 4 t 

2 


a/2 


i 2 


b - 4 sina + t sina -1 t 

2 


for 0 < t < 2 a/2 


( 19 ) 


„ V2 

Now, ( -4 + t ) cosa is greater than or equal to zero, and 4 — t is greater than or equal to 2. Hence, 

the distance is greater than or equal to 2. 


The distance while traversing the second segment in terms of the parametric equations (12) is 



s 2 = a -(4-2^2) cosa + tcosa + 2f-t 
+ [b - (4- 2 V 2 ) sina + tsina + 2 ] ” 


The derivative is 


= 2 a -(4-2 -n/ 2) cosa + tcosa + 2t - t][cosa - l] 
b 2 [b - (4 - 2 V 2 ) sina + t sina + 2 ] [sin a] 


The second derivative is 


d 2 's 2 


= 2 [cosa - l] ° +2 [sin a] ' 


which is positive. Hence the zero value for the first derivative gives a minimum. 
Setting the derivative equal to zero and solving for t gives 


= 3--\/2 - 


■1 + cosa 


Substituting this value for t into the original distance formula and some algebra give 


2 = a + (-1+ V 2 ) cosa - 1 + v/2 + sina 
+ b+(-l + V2) sina - cosa + 1] 


Since all the terms in the expression in the second bracket are positive, the distance is greater than or equal 
to 1. 

The distance while traversing the second segment in terms of the parametric equations (13) is 


s 2 = a + 2v/2cosa + tcosa -2 t 

2 


b + 2v/2 sina + tsina + 2 t 

2 


for 0 < t < 2 v/2 


( 25 ) 



t < 0-2- 


Now, 2a/ 2 cosa + tcosa - 2 

2 


t < -2. since a is less than or equal to the 

2 


expression inside the first bracket is less than or equal to -1, which implies the distance is greater than or 
equal to 1. 


7. The Feedback Equations 

Both aircraft are guided by onboard digital controllers. Hence, the desired flight path is given by a sequence 
of points: the positions the aircraft should be at the end of a control cycle. 

The feedback control law is a modified PID (Position-Integral-Derivative) that pivots on the velocity vector. 
If it pivoted on distance, the aircraft would be constantly lurching forward to the next point on its path. 
Hence, for this controller, the velocity vector plays the role of P, the acceleration plays the role of D, and the 
error between the actual point of the aircraft and the desired point plays the role of I. 

The aircraft is treated as a constant point of mass 1. Hence, the acceleration is proportional to the applied 
force. The distance between points is also normalized to 1. This last normalization is different from the 
normalization used in the analytic derivations for the idealized paths. This last normalization, of control- 
distance equal to 1, will be the one used for the rest of this paper and in the computer simulation. 

At the time interval k, let 

a(k) = current acceleration at time k 

v(k) = current velocity at time k 

s(k) = current position at time k 

v a (k) = desired velocity at time k 

s d (k) = desired position at time k 

x = control time interval 

The equations for the next time interval are 

a(k + 1) = a a(k) + /? [v(k) - v d (k) J + 5 |s(k) - s d (k)] 
v(k + 1 ) = v(k) + t a(k) 

= v(k) + r {a a(k) + (5 [v(k) - v d (k)] ■ + 8 [s(k) - s d (k)] } 


s(k + 1 ) = s(k) + r v(k) + a(k) 

= s(k) + r v(k) 

2 

+ T — { a a(k) + p [v(k) - v d (k)]+ S [s(k) - s d (k)] } 

(26) 


The acceleration is constant throughout the interval [k, k+1] while v(k+l) and s(k+l) are the values at the 
end of the interval. 



For the second equation, subtract v d (k) from both sides and use v d (k) =Vd(k+l). For the third equation, 
write 


s(k) + r v(k) = s d (k) + r v d (k) + (s(k) - s d (k) J + r (v(k) - v d (k) j 
= s d (k + 1) + (s(k) - s d (k))+ r (v(k) - v d (k) ) 

This gives 


a(k + 1) = a a(k) + /? [v(k) - v d (k)J+ 5 [s(k) - s d (k)J 

v(k + 1) - v d (k + 1) = ara(k)+ (1 + /?r)[v(k)- v d (k)]+^r [s(k)-s d (k)] 


s(k + 1 ) - s d (k + 1 ) 


~Y~ a a(k) + 


f 


v 


v 

r 2 ^ 
1 + — 8 

2 , 


' r 2 ^ 

T + —J3 

2 J 


[v(k)- 

[s(k) - s d (k)] 



(27) 


(28) 


This gives the coefficient matrix 


a (3 8 

ar 1 + /?r St 

2 2 2 

T n T i c- ^ 

a — r + p — 1 + 8 — 

L 2 2 2 . 

For the time and gain values 
x = l 


(29) 


a = - 0.001 


P = - 0.5 

5 = - 0 . 2 . 


(30) 


The eigenvalues are 0, 0.1995+0.2433i, and 0.1995-0.2433i, which are less than one. Hence the system is 
stable. A more realistic study would include a more detailed model of the aircraft and base the control 
parameters on the aircraft's performance. 


Continuing to choose numbers convenient for scaling, this study assumes an aircraft speed of 600 knots and 
a control-time interval of one second, which implies the five nautical mile separation requirement translates 
into a distance of 30 units in the simulation. 



The control law above can take the aircraft through the required turn of n/4 radians. As expected, there is a 
small overshoot at the corners. The effect of the overshoot is displayed and examined in section nine. 


8. The Turbulence Model 

This section describes the external turbulence applied to the aircraft. The assumption is that turbulence is 
the accumulation of small effects which implies it has a normal distribution. Since the flight path is two- 
dimensional, the turbulence has an x-component and a y-component. In this study the an x-component a y- 
component are independent 

For both components, the force is a constant over the control interval of one second. The generality of this 
assumption will be studied later in this section. 

The variants are the variance of the normal distribution, the correlation between the aircraft, and the 
correlation in time. This paper uses standard deviations of 1/10 and 1 for the normal distribution. For 
correlation between the aircraft, the two aircraft experience the same turbulence or experience independent 
turbulence. Time correlation is more complicated. 

Time correlation is introduced by having the mean of the distribution for step k+1 depend on the values 
chosen for step k. If x k is the value for the turbulence in step k, then the value for the turbulence in step 
k+1 is chosen from a normal distribution with mean ext for some positive constant c. All the distributions 
have the same variance o 2 

Suppose x k is the value for step k, and suppose the z i 's are from a normal distribution with mean zero and 
variance o 2 . Then x k+i is given by 


x k+1 - cx k +z k+l 

= c(cx k . 1 +z k )+z k+1 
k k-1 

= C Z\+C Z2 + ... + cz k + Z k + J 

(31) 


Using the standard results for the means and variances of independent variables, the means and variances 
for this stochastic process are 


mean 
var 


( x k) 
( x k) = 


mean 


(c Zj+C Z2+... + z k j — 0 


k-1 k-? 

varlc Zj+c z 2 + • • • ~F z k 


2 k-2 2 , 2k-4 2 , , _2 , 2 

= c cr + c cr +...+ C cr + a 


^ 1 - c 2k ^ 


1-c^ 


cr 


if c ^ 1 


J 


= ka z 


if c = 1 


(32) 


Using the result on expectation that E[ Zj Zj ] = 0 if the z's are independent variables with zero means, the 
covariance of the process is 



E [ ( x n+k -°)( x n “0)J 
= E 


= E 


c n+k 1 z i + ... + c k z n +c k 1 z n+1 ...+z n+k 

x ^c 11 " 1 Zi +... + z n 

2n+k-2 2 k 2 

C Z 1 +... + C z n 


( 33 ) 


C k Zc 

j=l 


2n-2j 


a 


i 2 n 

= c k — cr 2 ifc^l 

1-c 2 

= n cr 2 if c = 1 

It can be seen that if c < 1, then the covariance goes to zero as k, the distance between the two points, 
becomes large. Also, as n becomes large, the process approaches a stationary process: the covariance 
depends only on the distance between the variables. 

We next look at the effect of the turbulence (the stochastic process) on the control states of acceleration, 
velocity, and distance. There is a slight shift in notation since we follow the control theory convention of 
indexing the initial parameters with zero. Let y be the state vector and x the stochastic input. 

y(l) = Ay(0) + Bx(0) 
y(2) = Ay(l) + Bx(l) 

= A 2 y(0) + A B x(0) + B x( 1 ) 


y(n) = A n y(0)+ I 1 A 

k=0 


n-l-k 


Bx(k) 
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Since the system is stable, the first term converges to the desired acceleration, velocity, and position(s). 

Since the x(k)'s are normal with mean zero, the error from turbulence (the stochastic process) is normal with 
mean zero. No attempt has been made to derive the variance of the error although it could be obtained 
empirically from simulation. Section nine estimates the mean and variance for one set of turbulence 
parameters. 

The final topic in this section asks if the turbulence model technique of applying a constant force for a 
discrete interval is completely general. Can some type of average duplicate the effect of any function of 
force over that interval? The answer is no. Consider a point of mass 1, a time interval of 1, and the force 
function 


J 2 for 0 < t < 1/2 
[0 for 1/2 < t < 1 


( 35 ) 


At time t=l, the velocity and position are 



( 36 ) 


v = f(t) 
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2 

+ (l)(l/2) = 3/4 


To duplicate the result, a constant force a over the interval must satisfy the equations 

v = 1 =a( l) = a 
s = 3 / 4 = — [l] 2 =a/2 

2 (37) 


which is not possible. 

9. Miscellany on Perturbations 

The graph in figure 9 shows the aircraft making the separation-maneuver moving under feedback control 
with no perturbation present. Note the overshoot at the corners. 

The mean and standard deviation of the error for distance were estimated. The path in figure 9 lasts 320 
seconds which is 320 discrete control intervals. At the end of each control interval the difference between 
actual position and desired position was computed. This computation was performed for 3000 flight paths 
or 960,000 points. The results are mean = 3.7298e-4 and std = 0.1531. 



Fig. 9. Path of maneuvering aircraft moving with feedback. The marks on the axes indicate 
five-mile intervals 


The graph in figure 10 shows the aircraft making the separation-maneuver moving under feedback control 
with perturbation present. This perturbation is one of the more extreme ones with the variables initially 
chosen from the normal with standard deviation 1 and then given time correlation with c = 1/2. 

Once again, there were 3000 trials with 320 points per trial. For this case, the error had mean = 0.0068 and 
std = 4.3898. 
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Fig. 10. Path of maneuvering aircraft in the presence of perturbations. The marks on the axes are 
five-mile increments 


There are additional areas for investigation for perturbations. One item not covered in this study is when 
the perturbation has a drift, a constant non-zero value for its mean. 

Another item is whether or not it is possible to establish a high probability envelope for the path of the 
aircraft in the presence of perturbations. Such an envelope would imply that a separation algorithm that 
allowed for the envelope could be proved, and the need for studying the separation in the presence of 
perturbations would be eliminated. 

10. Choosing the Minimum Distance Point in a Sector 

Randomly choosing the minimum-distance point in the sector for a trial brings up two problems. The first 
problem is what is the actual distribution for air traffic. This is not known to the author. Since the usual 
response to such lack of information is to use the uniform distribution, the second problem is obtaining a 
distribution and demonstrating it is uniform. 

Suppose the sector is part of a circle of radius 1. Consider an arbitrary subsector as in figure 11. 



Fig. 11. Subsector inside a sector 


Suppose the subsector lies between angles p 1 and p 2 and radii r 1 and r 2 • The area of the subsector 
divided by the area of the one-eighth circle is 
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We have a uniform distribution in the sector if the probability of a point being in the subsector equals its 
proportional area. 

To this end, choose ni and n 2 independently from a uniform distribution, and form the point with angle 
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Hence, the probability that the point is in the subsector is equal to the relative area of the subsector which 
gives a uniform distribution for points in the sector. 


11. The Simulation Cases 

Eight Monte Carlo experiments were performed, each with 370,000,000 trials. 
The aircraft had identical perturbations or independent perturbations. 

The initial random variable was chosen with std = 1/10 or std = 1. 

The correlation constant was c = 0 or c = V 2 . 

There was no loss of separation in any of the trials. 



For each case, the experiment showed that the probability of more than 3 incidents in three years is less than 
0.10 at the 100( 1 - le-9 ) confidence level, which is the confidence level appropriate if there are 100 types of 
incidents. 


12. Minimum Distance Estimation 

It's satisfying that the separation algorithm handled all the perturbation cases, but it gives no insight with 
respect to the effect of the perturbations. This section attempts to remedy this by estimations of minimum 
distance. For each set of conditions, one million (le+6) trials were conducted, and the minimum distance of 
the two aircraft was recorded for each trial. For each set of conditions, the mean, standard deviations, and 
99% confidence interval for the minimum distance were computed. 

Since this comparison of conditions is not related to any FAA requirement, the investigation does not 
require meeting the confidence level of incidents, and the 99% confidence interval is sufficient to compare 
results. 


To make the results more comparable, each experiment used the same set of (le+6) points in the sector. The 
points were chosen according to the uniform-criteria in section ten with the angles and radii given by 

a k = n/4 + k n/ 4000 for k = 1, . . ., 1000 


r k = sqrt ( k/1000 ) for k = 1, . . ., 1000 . 


(40) 


The parameters that were varied were 

The perturbations for the two aircraft were either identical (pert2=pertl) or independent (Ind). 

The initial random variable was chosen from a normal distribution with mean = 0 and std = 1/10 
or std = 1. 

The correlation constant was 0 or Vi. 

The results for the eight cases are given in table 2. 

From an examination of the table, the major factor is the standard deviation of the original normal 
distribution. Once this standard deviation is large, the correlation factor becomes significant. 



Conditions 

mean 

std 

99% int 

Pertl=pert2 
Std = 1/10 
C = 0 

67.3279 

1.5910 

67.3238 

67.3320 

Pertl=pert2 
Std = 1 
C = 0 

65.9497 

1.7335 

65.9452 

65.9542 

Ind 

Std = 1/10 
C = 0 

67.1959 

1.6200 

67.1917 

67.2001 

Ind 

Std = 1 
C = 0 

63.0055 

2.8300 

62.9981 

63.0129 

Pertl=pert2 
Std = 1/10 
C = 1/2 

67.2951 

1.5941 

67.2910 

67.2992 

Pertl=pert2 
Std = 1/10 
C = 1/2 

65.3106 

1.8880 

65.3057 

65.3155 

Ind 

Std = 1/10 
C = 1/2 

67.0579 

1.6499 

67.0536 

67.0622 

Ind 

Std = 1 
C = 1/2 

60.5988 

3.6930 

60.5892 

60.6084 


Table 2. Estimated mean, standard deviation, and 99% confidence interval for minimum distance 

13. Conclusions 

The primary objective of this paper is to establish that an air traffic algorithm meets the FAA requirements 
in the presence of perturbations. 

There is a discussion of a representative FAA requirement, its probabilistic interpretation, and the number 
of trials needed in a Monte Carlo simulation. The algorithm chosen is flight separation for approaching 
aircraft. It is first shown that the minimum-distance point of the aircraft determines their flight angles. 

With this result in hand, the algorithm is described and an analytical proof of the algorithm is given for 
idealized flight paths. 

Next, two items are introduced for realism. A modified PID control law is proposed and shown to be stable. 
Once the control law is in place, perturbations can be introduced as external forces. The parameters of the 
perturbation are the standard deviation, the correlation between aircraft, and the time correlation. The 
stochastic properties of the perturbation are derived. Monte Carlo simulation shows the separation- 
algorithm meets a chosen FAA requirement for eight cases of the perturbation. A minimum-distance study 
shows the different perturbations have different effects. The natural extensions to this effort are to consider 
more than two aircraft, a more global setting, wind, and instrumentation errors. Wind, for instance, can be 
included by letting the random variables have a nonzero mean. How much can be established by realistic 
simulation remains an open problem. The method presented in this paper depends on the ability to execute 
the algorithm 100,000 times faster than real time. Whether such speeds can be achieved for realistic 
algorithms is an open question. 
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